Publisher: Pleasanton Weekly (Christian Trujano)
Date Published: July 10, 2026
Relevant To: SB 34 violation via legacy system data-labeling error; “search on behalf of federal agencies” workaround pattern; Mike Katz-Lacabe/Oakland Privacy
Verification Status: Verified
Notes: Confirmed via full-text fetch. Pleasanton, CA Police Department admitted at a July 7, 2026 City Council meeting that its legacy Motorola Vigilant ALPR system (30 cameras at ~12 intersections, installed 2020, active until October 2025) had allowed the San Diego Sector Border Patrol to access its license-plate data, in apparent violation of California SB 34 (bars sharing ALPR data with federal/out-of-state agencies or private entities). The violation was surfaced via a public records request by Mike Katz-Lacabe (Oakland Privacy director of research — already a named contributor to primary-source documents cataloged elsewhere in this library) using Oakland Privacy’s statewide “Agency Data Sharing Report,” which flagged dozens of other CA agencies with the same issue. PPD Lt. Nicholas Albert attributed the failure to human error: when other federal agency connections were removed from the system, “the San Diego Sector Border Patrol entry was inadvertently overlooked because it was listed under California rather than as a federal agency.” Whether data was actually accessed during the violation period is unknown/unconfirmed by either side. Pleasanton signed a new 5-year, $639,760 Flock Safety contract in September 2025 (54 replacement cameras) after testing 8 Flock cameras alongside the Motorola system since 2022; Albert claims the new Flock system prevents direct federal access, but Katz-Lacabe noted Flock still permits LOCAL police to run searches “on behalf of” federal agencies (FBI, DEA, Border Patrol, ICE) — a documented workaround pattern seen “in many, many places” that Pleasanton cannot technically prevent, and that Flock as a private company could change its data-sharing policies unilaterally without customer notification. Dan Morley of Indivisible Tri-Valley noted the city/police had previously assured the council no data was shared with federal agencies before this contract was approved. Directly useful comparative case for BPA: illustrates how an ALPR system’s audit process can miss a real violation for years due to a data-labeling error, and how vendor “no direct access” assurances can be technically true while masking a functional data-access workaround via search-on-behalf-of arrangements.